Papers
Topics
Authors
Recent
Search
2000 character limit reached

Directed-Graph Decryption

Updated 9 December 2025
  • Directed-graph decryption is a cryptographic methodology that applies trellis decoders to noise-enhanced high-memory convolutional codes for secure and efficient ciphertext recovery.
  • It leverages deliberate polynomial ambiguity and masking techniques to create exponential barriers against algebraic and information-set decoding attacks.
  • The approach offers post-quantum security with scalable hardware/software implementations, achieving constant per-bit processing and high throughput.

Directed-graph decryption is a cryptographic methodology that utilizes directed-graph-based algorithms, specifically trellis decoders, to efficiently and securely decrypt ciphertexts encoded with noise-enhanced high-memory convolutional codes. This approach is structurally distinct from traditional code-based cryptosystems, presenting both algebraic and complexity-theoretic challenges to adversaries, particularly in the context of post-quantum cryptography. Directed-graph decryption leverages polynomial ambiguity, introduced via encoded masking and deliberate polynomial-division noise, to create substantial barriers for algebraic and information-set decoding (ISD) attacks, while still allowing authorized recipients polynomial-time decryption with constant per-bit computational cost (Ariel, 2 Dec 2025).

1. Algebraic Construction: High-Memory Convolutional Codes

Directed-graph decryption schemes operate by encoding a message polynomial m(x)∈F2[x]m(x) \in \mathbb{F}_2[x] (degree <K< K) using a convolutional code generator matrix with enhanced memory. This generator comprises a base matrix Gp(x)=[p0(x) … pn−1(x)]G_p(x) = [p_0(x)\, \ldots\, p_{n-1}(x)] of memory pp and a set of high-memory polynomials GQ(x)=[q0(x) … qn−1(x)]G_Q(x) = [q_0(x)\, \ldots\, q_{n-1}(x)] with degrees up to qq, combined element-wise to yield

GpQ(x)=[p0(x)q0(x), …, pn−1(x)qn−1(x)].G_{pQ}(x) = [p_0(x)q_0(x),\, \ldots,\, p_{n-1}(x)q_{n-1}(x)].

A masking matrix G~\tilde{G} of rank ℓ≪K\ell \ll K is added for polynomial ambiguity. The dense public generator G(x)G(x) is constructed by scrambling and permuting <K< K0 via invertible matrices <K< K1 and <K< K2. The public encoder is given by

<K< K3

where <K< K4 is a random error polynomial of specified Hamming weight. The private key contains <K< K5 and a CRC-polynomial <K< K6 for failure detection (Ariel, 2 Dec 2025).

2. Trellis Modeling and Polynomial Ambiguity

The decryption process models the convolutional code using a trellis <K< K7:

  • Nodes: <K< K8, with <K< K9 for Gp(x)=[p0(x) … pn−1(x)]G_p(x) = [p_0(x)\, \ldots\, p_{n-1}(x)]0 but Gp(x)=[p0(x) … pn−1(x)]G_p(x) = [p_0(x)\, \ldots\, p_{n-1}(x)]1 for the honest decoder.
  • Edges: Each state Gp(x)=[p0(x) … pn−1(x)]G_p(x) = [p_0(x)\, \ldots\, p_{n-1}(x)]2 at time Gp(x)=[p0(x) … pn−1(x)]G_p(x) = [p_0(x)\, \ldots\, p_{n-1}(x)]3 branches to Gp(x)=[p0(x) … pn−1(x)]G_p(x) = [p_0(x)\, \ldots\, p_{n-1}(x)]4 for both Gp(x)=[p0(x) … pn−1(x)]G_p(x) = [p_0(x)\, \ldots\, p_{n-1}(x)]5, labeled by Gp(x)=[p0(x) … pn−1(x)]G_p(x) = [p_0(x)\, \ldots\, p_{n-1}(x)]6.

The presence of Gp(x)=[p0(x) … pn−1(x)]G_p(x) = [p_0(x)\, \ldots\, p_{n-1}(x)]7 (mask) and the indeterminate polynomial-division remainders generates up to Gp(x)=[p0(x) … pn−1(x)]G_p(x) = [p_0(x)\, \ldots\, p_{n-1}(x)]8 valid “demasked” polynomial candidates for each ciphertext. The trellis is extended with Gp(x)=[p0(x) … pn−1(x)]G_p(x) = [p_0(x)\, \ldots\, p_{n-1}(x)]9 “ambiguity edges” at the start, accommodating all possible linear combinations from the rowspace of pp0. After ambiguity is resolved, decoding proceeds as a standard convolutional trellis over pp1 memory stages (Ariel, 2 Dec 2025).

3. Directed-Graph Decryption Algorithm and Complexity

Decryption is realized through the following stages:

  1. Invert permutation: Apply pp2 to the ciphertext.
  2. Mask ambiguity: For each candidate in the pp3-sized linear span of pp4, generate a demasked vector.
  3. Polynomial division: For each demasked candidate, divide component streams by their corresponding pp5, discard remainders, and reinterleave.
  4. Parallel trellis decoding: Launch pp6 parallel Viterbi decoders, each working on a pp7 memory trellis of length pp8.
  5. Verification: Use a CRC check to identify the valid plaintext, back-transform by pp9 if successful.

The honest decryption complexity is GQ(x)=[q0(x) … qn−1(x)]G_Q(x) = [q_0(x)\, \ldots\, q_{n-1}(x)]0, which is GQ(x)=[q0(x) … qn−1(x)]G_Q(x) = [q_0(x)\, \ldots\, q_{n-1}(x)]1 since GQ(x)=[q0(x) … qn−1(x)]G_Q(x) = [q_0(x)\, \ldots\, q_{n-1}(x)]2 are small constants (e.g., GQ(x)=[q0(x) … qn−1(x)]G_Q(x) = [q_0(x)\, \ldots\, q_{n-1}(x)]3), and the cost per bit is constant. Adversarial decryption, lacking GQ(x)=[q0(x) … qn−1(x)]G_Q(x) = [q_0(x)\, \ldots\, q_{n-1}(x)]4 and the scramble/permutation matrices, requires an exponential search (GQ(x)=[q0(x) … qn−1(x)]G_Q(x) = [q_0(x)\, \ldots\, q_{n-1}(x)]5 for K-dimensional codes) or algebraic attacks of equivalent cost. These operations are exponential in GQ(x)=[q0(x) … qn−1(x)]G_Q(x) = [q_0(x)\, \ldots\, q_{n-1}(x)]6 (Ariel, 2 Dec 2025).

4. Cryptanalytic Security and Comparison with Classic McEliece

Directed-graph decryption with noise-enhanced memory convolutional codes (labeled "MCC" for Masked Convolutional Codes, Editor’s term) achieves a substantial security improvement over Classic McEliece. For code parameters GQ(x)=[q0(x) … qn−1(x)]G_Q(x) = [q_0(x)\, \ldots\, q_{n-1}(x)]7, GQ(x)=[q0(x) … qn−1(x)]G_Q(x) = [q_0(x)\, \ldots\, q_{n-1}(x)]8, effective error weight GQ(x)=[q0(x) … qn−1(x)]G_Q(x) = [q_0(x)\, \ldots\, q_{n-1}(x)]9, the ISD complexity is

qq0

compared to qq1 for a qq2 Goppa code in Classic McEliece. This yields a margin exceeding qq3 operations. Under Grover quantum speedup, margins remain greater than qq4. Thus, the system offers security exceeding qq5 against both classical and quantum ISD attacks (Ariel, 2 Dec 2025).

Scheme Key Parameters Best ISD Complexity Security Margin (vs Classic)
Classic McEliece qq6 qq7 Baseline
MCC (this scheme) qq8 qq9 GpQ(x)=[p0(x)q0(x), …, pn−1(x)qn−1(x)].G_{pQ}(x) = [p_0(x)q_0(x),\, \ldots,\, p_{n-1}(x)q_{n-1}(x)].0

5. Scalability, Per-Bit Cost, and Parallelism

The per-bit computational cost for honest decryption is

GpQ(x)=[p0(x)q0(x), …, pn−1(x)qn−1(x)].G_{pQ}(x) = [p_0(x)q_0(x),\, \ldots,\, p_{n-1}(x)q_{n-1}(x)].1

as GpQ(x)=[p0(x)q0(x), …, pn−1(x)qn−1(x)].G_{pQ}(x) = [p_0(x)q_0(x),\, \ldots,\, p_{n-1}(x)q_{n-1}(x)].2 and GpQ(x)=[p0(x)q0(x), …, pn−1(x)qn−1(x)].G_{pQ}(x) = [p_0(x)q_0(x),\, \ldots,\, p_{n-1}(x)q_{n-1}(x)].3 are constant parameters, invariant with message length GpQ(x)=[p0(x)q0(x), …, pn−1(x)qn−1(x)].G_{pQ}(x) = [p_0(x)q_0(x),\, \ldots,\, p_{n-1}(x)q_{n-1}(x)].4. This enables decryption complexity to scale linearly in the ciphertext size, with modern hardware (FPGAs, GPUs, SIMD CPUs) able to accommodate the necessary GpQ(x)=[p0(x)q0(x), …, pn−1(x)qn−1(x)].G_{pQ}(x) = [p_0(x)q_0(x),\, \ldots,\, p_{n-1}(x)q_{n-1}(x)].5 ACS modules (e.g., GpQ(x)=[p0(x)q0(x), …, pn−1(x)qn−1(x)].G_{pQ}(x) = [p_0(x)q_0(x),\, \ldots,\, p_{n-1}(x)q_{n-1}(x)].6 for GpQ(x)=[p0(x)q0(x), …, pn−1(x)qn−1(x)].G_{pQ}(x) = [p_0(x)q_0(x),\, \ldots,\, p_{n-1}(x)q_{n-1}(x)].7), supporting gigabit-per-second throughput on sizable messages. Arbitrary plaintext lengths are supported without cost increase per bit (Ariel, 2 Dec 2025).

6. Hardware and Software Implementation

Directed-graph decryption benefits from inherent parallelism. Typical hardware architectures integrate:

  • A matrix-multiply/unmask block, polynomial-division engine, and GpQ(x)=[p0(x)q0(x), …, pn−1(x)qn−1(x)].G_{pQ}(x) = [p_0(x)q_0(x),\, \ldots,\, p_{n-1}(x)q_{n-1}(x)].8-bit demultiplexer to feed a bank of GpQ(x)=[p0(x)q0(x), …, pn−1(x)qn−1(x)].G_{pQ}(x) = [p_0(x)q_0(x),\, \ldots,\, p_{n-1}(x)q_{n-1}(x)].9 parallel Viterbi cores.
  • FPGA implementations use pipelined ACS arrays across G~\tilde{G}0 stages, sharing on-chip RAM.
  • ASIC/SoC realizations involve dedicated polynomial dividers and Viterbi cores connected via broadcast switches.
  • On software platforms, each mask candidate is mapped to a thread or vector lane, using bit-packed ACS updates and vector reductions for minimum Hamming weight computation.

Example performance measures for representative parameters (G~\tilde{G}1) are:

  • FPGA (XC7A200T): G~\tilde{G}20.8 Gbit/s decryption at 200 MHz clock
  • ARM Neon (SW): G~\tilde{G}3200 Mbit/s per core (128-bit SIMD)

This high parallelism and constant per-bit cost allow the scheme to provide both strong post-quantum security and practical throughput in contemporary hardware and software environments (Ariel, 2 Dec 2025).

Definition Search Book Streamline Icon: https://streamlinehq.com
References (1)

Topic to Video (Beta)

No one has generated a video about this topic yet.

Whiteboard

No one has generated a whiteboard explanation for this topic yet.

Follow Topic

Get notified by email when new papers are published related to Directed-Graph Decryption.